Neosense - Multipurpose WordPress Theme | WordPress < 1.8 - Arbitrary File Upload

2016-09-19 00:00
Walter Hop

Strategic Overview

Vulnerability Overview

The Neosense theme before 1.8 for WordPress has qquploader unrestricted file upload via qquploader ajax file uploader.

Technical Analysis

REMEDIATION: Update to version 1.8, or a newer patched version --- IDENTIFIER: CWE-434 (Unrestricted Upload of File with Dangerous Type) The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C